RURussian Federationconfidence: 75G0035
ENERGETIC BEARENERGETIC BEAR
Also known as: BERSERK BEAR · ALLANITE · CASTLE · DYMALLOY · TG-4192 · Dragonfly · Crouching Yeti · Group 24 · Havex · Koala Team · IRON LIBERTY · G0035 · ATK6 · ITG15 · BROMINE · Blue Kraken · Ghost Blizzard · ENERGETIC BEAR
Origin
RU
Known aliases
18
Target sectors
2
Attribution
State-sponsored
Profile
ENERGETIC BEAR is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as BERSERK BEAR, ALLANITE, CASTLE (and 14 more). Operational targeting focuses on the Private sector and Government sectors. Documented victim organisations include United States, Germany, Turkey and 7 other named victims. Original record: A Russian group that collects intelligence on the energy industry.
Aliases· 18
BERSERK BEARALLANITECASTLEDYMALLOYTG-4192DragonflyCrouching YetiGroup 24HavexKoala TeamIRON LIBERTYATK6ITG15BROMINEBlue KrakenGhost BlizzardENERGETIC BEAR
Target sectors· 2
Private sectorGovernment
Known victims· 10
- United States
- Germany
- Turkey
- China
- Spain
- France
- Ireland
- Japan
- Italy
- Poland
MITRE ATT&CK Group crosswalk
References
- https://www.gov.uk/government/publications/russias-fsb-malign-cyber-activity-factsheet/russias-fsb-malign-activity-factsheet
- https://web.archive.org/web/20161020180305/http://www.scmagazineuk.com/iran-and-russia-blamed-for-state-sponsored-espionage/article/330401/
- https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2014/Dragonfly_Threat_Against_Western_Energy_Suppliers.pdf
- http://www.netresec.com/?page=Blog&month=2014-10&post=Full-Disclosure-of-Havex-Trojans
- https://threatpost.com/energy-watering-hole-attack-used-lightsout-exploit-kit/104772/
- https://www.cfr.org/interactive/cyber-operations/crouching-yeti
- https://www.reuters.com/article/us-ukraine-cyber-attack-energy-idUSKBN1521BA
- https://dragos.com/wp-content/uploads/CrashOverride-01.pdf
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.